QB 4
QB 4
QB 4
2. What are the three general categories of computer systems that can contain
digitalevidence?
A. Desktop, laptop, server
B. Personal computer, Internet, mobile telephone
C. Hardware, software, networks
D. Open computer systems, communication systems, and embedded
systems
10. Private networks can be a richer source of evidence than the Internet because:
A. They retain data for longer periods of time.
B. Owners of private networks are more cooperative with law enforcement.
C. Private networks contain a higher concentration of digital evidence.
D. All the above.
11. Due to caseload and budget constraints, often computer security professionals
attempt to
limit the damage and close each investigation as quickly as possible. Which of the
following is
NOT a significant drawback to this approach?
A. Each unreported incident robs attorneys and law enforcement personnel of an
opportunity
to learn about the basics of computer-related crime.
B. Responsibility for incident resolution frequently does not reside with the
security
professional, but with management.
C. This approach results in under-reporting of criminal activity, deflating
statistics that are
used to allocate corporate and government spending on combating computer-related
crime.
D. Computer security professionals develop loose evidence processing habits that
can make
it more difficult for law enforcement personnel and attorneys to prosecute an
offender.
None of the above
12. The criminological principle which states that, when anyone, or anything,
enters a crime
scene he/she takes something of the scene with him/her, and leaves something of
himself/herself
behind, is:
A. Locard’s Exchange Principle
B. Differential Association Theory
C. Beccaria’s Social Contract
D. None of the above
13. The author of a series of threatening e-mails consistently uses “im” instead of
“I’m.” This
is an example of:
A. An individual characteristic
B. An incidental characteristic
C. A class characteristic
D. An indeterminate characteristic
14. Personal computers and networks are often a valuable source of evidence. Those
involved with should be comfortable with this technology.
A. Criminal investigation
B. Prosecution
C. Defense work
D. All of the above
16. The digital evidence are used to establish a credible link between
A. Attacker and victim and the crime scene
B. Attacker and the crime scene
C. Victim and the crime scene
D. Attacker and Information
18. From the two given statements 1 and 2, select the correct option from a-d.
a. Original media can be used to carry out digital investigation process.
b. By default, every part of the victim’s computer is considered as unreliable.
A. a and b both are true
B. a is true and b is false
C. a and b both are false
D. a is false and b is true
19. The evidences or proof can be obtained from the electronic source is called the
A. digital evidence
B. demonstrative evidence
C. Explainable evidence
D. substantial evidence
22. Photographs, videos, sound recordings, X-rays, maps drawing, graphs, charts is
a
a type of _
A. Illustrative evidence
B. Electronic evidence
C. Documented evidence
D. Explainable evidence
25. When an incident takes place, a criminal will leave a hint evidence at the
scene and remove a
hint from the scene which is called as
A. Locard’s Exchange principle
B. Anderson’s Exchange principle
C. Charles’s Anthony principle
D. Kevin Ashton principle
30.The process of ensuring that providing or obtaining the data that you have
collected is similar
to the data provided or presented in a court is known as
A. Evidence validation
B. Relative evidence
C. Best evidence
D. Illustrative evidence
31.When cases got to trial your forensics examiner play one of role.
A. 2
B. 4
C. 3
D. 5
True or False
Questions
1. Digital evidence is only useful in a court of law.
A. True
B. False
5. Digital evidence can be duplicated exactly without any changes to the original
data.
A. True
B. False
6. Computers were involved in the investigations into both World Trade Center
attacks.
A. True
B. False
10. The aim of a forensic examination is to prove with certainty what occurred.
A. True
B. False
11. Even digital investigations that do not result in legal action can benefit from
principles of forensic science.
A. True
B. False